Логотип exploitDog
bind:CVE-2002-0286
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2002-0286

Количество 2

Количество 2

nvd логотип

CVE-2002-0286

больше 23 лет назад

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-g6rv-jcq2-9j99

больше 3 лет назад

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0286

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
github логотип
GHSA-g6rv-jcq2-9j99

The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу